Drop any Surgeon-exported package (.zip) to verify its signed lineage: every artifact's SHA-256 is recomputed against the in-toto/DSSE attestation and the signature is checked. Signed creation is the product — universal verification is what makes the signature worth anything.
Command-line equivalent ships in every
package: python tools/verify_attestation.py package.zip